Description
This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated user remote
code execution on the IdentityIQ server due to improper input validation of
submitted web service API content.
Published: 2026-09-28
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

This vulnerability allows an attacker to execute arbitrary code on the SailPoint IdentityIQ server without authentication. It stems from improper validation of data submitted through the web service API. The lack of input validation enables malicious content to be processed, leading to full server compromise. The weakness manifests as a classic input validation flaw (CWE‑20).

Affected Systems

All versions of SailPoint IdentityIQ are affected. The vulnerability is present in every release of the product as the input validation issue has not been addressed yet. No specific version boundary is given, so any deployment of IdentityIQ is at risk.

Risk and Exploitability

The CVSS score of 9.6 classifies this issue as critical. EPSS information is not available, but the fact that the vulnerability is remote, unauthenticated, and powerful code execution suggests a high likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, but that does not reduce its severity or potential impact. An attacker can exploit the flaw by sending crafted API requests to the IdentityIQ server over the network; no local privilege or user interaction is required. This creates a very high risk for organizations running unpatched systems.

Generated by OpenCVE AI on September 28, 2026 at 17:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest SailPoint IdentityIQ security patch that addresses the input validation flaw
  • Disable or restrict external access to exposed web service API endpoints until the patch is deployed
  • Implement strict input validation and sanitization on all API payloads to prevent malformed data from being processed
  • Monitor inbound traffic for anomalous API activity and raise alerts for attempts to submit overly large or malformed payloads

Generated by OpenCVE AI on September 28, 2026 at 17:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Sailpoint Technologies
Sailpoint Technologies identityiq
Vendors & Products Sailpoint Technologies
Sailpoint Technologies identityiq

Mon, 28 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.
Title SailPoint IdentityIQ Improper Form Validation Vulnerability
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Sailpoint Technologies Identityiq
cve-icon MITRE

Status: PUBLISHED

Assigner: SailPoint

Published:

Updated: 2026-09-28T18:02:57.009Z

Reserved: 2026-06-15T16:30:51.596Z

Link: CVE-2026-12342

cve-icon Vulnrichment

Updated: 2026-09-28T17:53:16.146Z

cve-icon NVD

Status : Received

Published: 2026-09-28T16:17:13.460

Modified: 2026-09-28T18:17:21.410

Link: CVE-2026-12342

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T17:45:04Z

Weaknesses
  • CWE-20

    Improper Input Validation